drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in Linux RT (Live Patch 1 SLE 15 SP4)
Name: |
Mehrere Probleme in Linux RT (Live Patch 1 SLE 15 SP4) |
|
ID: |
SUSE-SU-2023:2371-1 |
|
Distribution: |
SUSE |
|
Plattformen: |
SUSE Linux Enterprise Micro 5.3, SUSE Linux Enterprise Real Time 15 SP4, SUSE Linux Enterprise High Performance Computing 15 SP4, SUSE Linux Enterprise Server 15 SP4, SUSE Linux Enterprise Server for SAP Applications 15 SP4, SUSE Linux Enterprise Micro 5.4, SUSE Linux Enterprise Live Patching 15-SP4 |
|
Datum: |
Mo, 5. Juni 2023, 20:26 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0386
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23454
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28464
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0461
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2162
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1989
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1281 |
|
Applikationen: |
RT-Preempt-Realtime-Patch |
|
Originalnachricht |
--===============5606811940940231977== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit
# Security update for the Linux Kernel RT (Live Patch 1 for SLE 15 SP4)
Announcement ID: SUSE-SU-2023:2371-1 Rating: important References:
* #1207188 * #1208911 * #1209683 * #1210499 * #1210500 * #1210662 * #1211111
Cross-References:
* CVE-2023-0386 * CVE-2023-0461 * CVE-2023-1281 * CVE-2023-1989 * CVE-2023-2162 * CVE-2023-23454 * CVE-2023-28464
CVSS scores:
* CVE-2023-0386 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-0386 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-0461 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-0461 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1281 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1281 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1989 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1989 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-2162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-2162 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2023-23454 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-23454 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-28464 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-28464 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4
An update that solves seven vulnerabilities can now be installed.
## Description:
This update for the Linux Kernel 5.14.21-150400_15_5 fixes several issues.
The following security issues were fixed:
* CVE-2023-28464: Fixed user-after-free that could lead to privilege escalation in hci_conn_cleanup in net/uetooth/hci_conn.c (bsc#1211111). * CVE-2023-1989: Fixed a use after free in btsdio_remove (bsc#1210500). * CVE-2023-0386: Fixed privileges escalation for low-privileged users in the OverlayFS subsystem (bsc#1210499). * CVE-2023-1281: Fixed use after free that could lead to privilege escalation in tcindex (bsc#1209683). * CVE-2023-2162: Fixed an use-after-free flaw in iscsi_sw_tcp_session_create (bsc#1210662). * CVE-2023-0461: Fixed use-after-free in icsk_ulp_data (bsc#1208911). * CVE-2023-23454: Fixed a type-confusion in the CBQ network scheduler (bsc#1207188).
## Patch Instructions:
To install this SUSE Important update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2023-2371=1 SUSE-SLE- Module-Live-Patching-15-SP4-2023-2370=1
## Package List:
* SUSE Linux Enterprise Live Patching 15-SP4 (x86_64) * kernel-livepatch-5_14_21-150400_15_5-rt-debuginfo-6-150400.2.2 * kernel-livepatch-5_14_21-150400_15_8-rt-debuginfo-5-150400.2.2 * kernel-livepatch-SLE15-SP4-RT_Update_1-debugsource-6-150400.2.2 * kernel-livepatch-5_14_21-150400_15_5-rt-6-150400.2.2 * kernel-livepatch-5_14_21-150400_15_8-rt-5-150400.2.2 * kernel-livepatch-SLE15-SP4-RT_Update_2-debugsource-5-150400.2.2
## References:
* https://www.suse.com/security/cve/CVE-2023-0386.html * https://www.suse.com/security/cve/CVE-2023-0461.html * https://www.suse.com/security/cve/CVE-2023-1281.html * https://www.suse.com/security/cve/CVE-2023-1989.html * https://www.suse.com/security/cve/CVE-2023-2162.html * https://www.suse.com/security/cve/CVE-2023-23454.html * https://www.suse.com/security/cve/CVE-2023-28464.html * https://bugzilla.suse.com/show_bug.cgi?id=1207188 * https://bugzilla.suse.com/show_bug.cgi?id=1208911 * https://bugzilla.suse.com/show_bug.cgi?id=1209683 * https://bugzilla.suse.com/show_bug.cgi?id=1210499 * https://bugzilla.suse.com/show_bug.cgi?id=1210500 * https://bugzilla.suse.com/show_bug.cgi?id=1210662 * https://bugzilla.suse.com/show_bug.cgi?id=1211111
--===============5606811940940231977== Content-Type: text/html; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit
<div class="container"> <h1>Security update for the Linux Kernel RT (Live Patch 1 for SLE 15 SP4)</h1>
<table class="table table-striped table-bordered"> <tbody> <tr> <th>Announcement ID:</th> <td>SUSE-SU-2023:2371-1</td> </tr> <tr> <th>Rating:</th> <td>important</td> </tr> <tr> <th>References:</th> <td> <ul> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1207188">#1207188</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1208911">#1208911</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1209683">#1209683</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1210499">#1210499</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1210500">#1210500</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1210662">#1210662</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1211111">#1211111</a> </li> </ul> </td> </tr> <tr> <th> Cross-References: </th> <td> <ul> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2023-0386.html">CVE-2023-0386</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2023-0461.html">CVE-2023-0461</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2023-1281.html">CVE-2023-1281</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2023-1989.html">CVE-2023-1989</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2023-2162.html">CVE-2023-2162</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2023-23454.html">CVE-2023-23454</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2023-28464.html">CVE-2023-28464</a> </li> </ul> </td> </tr> <tr> <th>CVSS scores:</th> <td> <ul class="list-group"> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-0386</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-0386</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-0461</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-0461</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-1281</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-1281</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-1989</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-1989</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.0</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-2162</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.0</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-2162</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">5.5</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-23454</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-23454</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">5.5</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-28464</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2023-28464</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> </ul> </td> </tr> <tr> <th>Affected Products:</th> <td> <ul class="list-group"> <li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP4</li> <li class="list-group-item">SUSE Linux Enterprise Live Patching 15-SP4</li> <li class="list-group-item">SUSE Linux Enterprise Micro 5.3</li> <li class="list-group-item">SUSE Linux Enterprise Micro 5.4</li> <li class="list-group-item">SUSE Linux Enterprise Real Time 15 SP4</li> <li class="list-group-item">SUSE Linux Enterprise Server 15 SP4</li> <li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP4</li> </ul> </td> </tr> </tbody> </table>
<p>An update that solves seven vulnerabilities can now be installed.</p>
<h2>Description:</h2> <p>This update for the Linux Kernel 5.14.21-150400_15_5 fixes several issues.</p> <p>The following security issues were fixed:</p> <ul> <li>CVE-2023-28464: Fixed user-after-free that could lead to privilege escalation in hci_conn_cleanup in net/uetooth/hci_conn.c (bsc#1211111).</li> <li>CVE-2023-1989: Fixed a use after free in btsdio_remove (bsc#1210500).</li> <li>CVE-2023-0386: Fixed privileges escalation for low-privileged users in the OverlayFS subsystem (bsc#1210499).</li> <li>CVE-2023-1281: Fixed use after free that could lead to privilege escalation in tcindex (bsc#1209683).</li> <li>CVE-2023-2162: Fixed an use-after-free flaw in iscsi_sw_tcp_session_create (bsc#1210662).</li> <li>CVE-2023-0461: Fixed use-after-free in icsk_ulp_data (bsc#1208911).</li> <li>CVE-2023-23454: Fixed a type-confusion in the CBQ network scheduler (bsc#1207188).</li> </ul>
<h2>Patch Instructions:</h2> <p> To install this SUSE Important update use the SUSE recommended installation methods like YaST online_update or "zypper patch".<br/>
Alternatively you can run the command listed for your product: </p> <ul class="list-group"> <li class="list-group-item"> SUSE Linux Enterprise Live Patching 15-SP4 <br/> <code>zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2023-2371=1 SUSE-SLE-Module-Live-Patching-15-SP4-2023-2370=1</code> </li> </ul>
<h2>Package List:</h2> <ul> <li> SUSE Linux Enterprise Live Patching 15-SP4 (x86_64) <ul> <li>kernel-livepatch-5_14_21-150400_15_5-rt-debuginfo-6-150400.2.2</li> <li>kernel-livepatch-5_14_21-150400_15_8-rt-debuginfo-5-150400.2.2</li> <li>kernel-livepatch-SLE15-SP4-RT_Update_1-debugsource-6-150400.2.2</li> <li>kernel-livepatch-5_14_21-150400_15_5-rt-6-150400.2.2</li> <li>kernel-livepatch-5_14_21-150400_15_8-rt-5-150400.2.2</li> <li>kernel-livepatch-SLE15-SP4-RT_Update_2-debugsource-5-150400.2.2</li> </ul> </li> </ul>
<h2>References:</h2> <ul> <li> <a href="https://www.suse.com/security/cve/CVE-2023-0386.html">https://www.suse.com/security/cve/CVE-2023-0386.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2023-0461.html">https://www.suse.com/security/cve/CVE-2023-0461.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2023-1281.html">https://www.suse.com/security/cve/CVE-2023-1281.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2023-1989.html">https://www.suse.com/security/cve/CVE-2023-1989.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2023-2162.html">https://www.suse.com/security/cve/CVE-2023-2162.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2023-23454.html">https://www.suse.com/security/cve/CVE-2023-23454.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2023-28464.html">https://www.suse.com/security/cve/CVE-2023-28464.html</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1207188">https://bugzilla.suse.com/show_bug.cgi?id=1207188</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1208911">https://bugzilla.suse.com/show_bug.cgi?id=1208911</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1209683">https://bugzilla.suse.com/show_bug.cgi?id=1209683</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1210499">https://bugzilla.suse.com/show_bug.cgi?id=1210499</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1210500">https://bugzilla.suse.com/show_bug.cgi?id=1210500</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1210662">https://bugzilla.suse.com/show_bug.cgi?id=1210662</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1211111">https://bugzilla.suse.com/show_bug.cgi?id=1211111</a> </li> </ul> </div>
--===============5606811940940231977==--
|
|
|
|